โ† Back to PocketPals

Privacy Policy

Effective March 9, 2026 ยท NuStack Digital Ventures LLC

What We Collect

From parents and guardians: Email address, display name, and a PIN you choose to protect the parent dashboard. This information is required to create and manage your account.

From children (with parental consent): First name, age range (3โ€“4, 5โ€“7, or 8โ€“12), conversation transcripts (text only), and lesson progress. We do not collect full names, addresses, phone numbers, or location data from children.

Voice and audio: Voice audio is processed in real time for speech recognition and is NOT stored. Only text transcripts of conversations are saved.

Usage data: Session length, features used, and streak data โ€” used to improve the product. Not sold or shared with advertisers.

How We Use Your Data

We do not use your data for behavioral advertising. We do not sell your data to any third party.

COPPA Compliance

PocketPals is built for children under 13 and is fully compliant with the Children's Online Privacy Protection Act (COPPA). We do not collect personal information from children without verifiable parental consent. The parent creates the account and consents on behalf of the child during onboarding.

For full details on how we comply with COPPA, see our COPPA Compliance Notice.

Your Parental Rights

To exercise any of these rights, email privacy@pocketpals.app or use Parent Settings within the app. We respond within 30 days.

Subprocessors

We use the following third-party subprocessors to operate PocketPals. Each has signed a Data Processing Agreement (DPA) with us governing how they handle your data:

Subprocessor Purpose Child data accessed
Anthropic, PBCBuddy LLM responses (Claude)Yes โ€” conversation text. Anthropic does not train on PocketPals data.
OpenAI, LLCSpeech-to-text (Whisper STT)Yes โ€” child voice audio chunks, immediately discarded post-transcription
ElevenLabs, Inc.Buddy voice synthesis (TTS)Indirect โ€” Buddy reply text only, no child voice input sent
Supabase, Inc.Database, auth, storage (us-east-1)Yes โ€” child profile, transcripts, memory facts
Vercel, Inc.Application hosting, edge computeIn transit only โ€” transient request data
Stripe, Inc.Web pathway parent payment + COPPA verificationNo child data โ€” parent billing only
RevenueCat, Inc.Native pathway subscription managementNo child data โ€” parent subscription state only
Apple Inc.iOS in-app billingNo child data โ€” parent App Store account only
Google LLCAndroid in-app billingNo child data โ€” parent Play Store account only
ResendTransactional email (parents)Indirect โ€” parent email + child first name in digest only
PostHog Inc.Product analyticsYes โ€” UUID + event names only. Never first names or transcripts.
Sentry, Inc.Error monitoringIndirect โ€” scrubbed payloads only, no child PII
Clerk, Inc.Operator surface authenticationNo child data at launch โ€” ops surface only
Inngest, Inc.Background job processingYes โ€” UUIDs and operation types only
Doppler, Inc.Secrets managementNo user data
Cloudflare, Inc.DNS, edge securityIn transit only

We do not share your child's data with any third party for advertising, marketing, or analytics outside of the subprocessors listed above.

Data Retention

Voice transcripts are retained for 90 days, then converted to summaries. Summaries are retained while the account is active plus 30 days. Moderation and safety events are retained for 24 months. Parental consent records are retained for 7 years. Audit logs are retained indefinitely. Upon account deletion (by the parent or by inactivity), all child data is deleted within 30 days and you will receive a confirmation email.

Data type Retention period
Voice transcripts90 days, then summary-only
Conversation summariesWhile account active + 30 days
Moderation & safety events24 months
Parental consent records7 years
Audit logsIndefinite

Security

All data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Parent PINs are hashed using bcrypt. Our database uses row-level security โ€” your child's data is only accessible to your account. We conduct periodic security reviews.

California Parents (CCPA)

California residents have the right to know what personal information we collect, request deletion, and opt out of any sale of personal information. We do not sell personal information. Contact us at privacy@pocketpals.app to exercise your rights.

EU and UK Parents (GDPR)

Parents in the EU and UK have rights to access, rectification, erasure, portability, restriction, and objection. We respond within 30 days. Contact: privacy@pocketpals.app.

Contact Us

Questions about this privacy policy or your data?

privacy@pocketpals.app

NuStack Digital Ventures LLC ยท Wyoming ยท We respond within 30 days.

Privacy Policy v3 โ€” 2026-04-25 ยท NuStack Digital Ventures LLC ยท Wyoming